Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2024-02-06 CVE-2024-1255 Information Exposure vulnerability in Sepidz Sepidzdigitalmenu
A vulnerability has been found in sepidz SepidzDigitalMenu up to 7.1.0728.1 and classified as problematic.
network
low complexity
sepidz CWE-200
7.5
2024-02-06 CVE-2023-40545 Missing Authentication for Critical Function vulnerability in Pingidentity Pingfederate 11.3.0
Authentication bypass when an OAuth2 Client is using client_secret_jwt as its authentication method on affected 11.3 versions via specially crafted requests.
network
low complexity
pingidentity CWE-306
critical
9.8
2024-02-06 CVE-2024-1048 Incomplete Cleanup vulnerability in multiple products
A flaw was found in the grub2-set-bootflag utility of grub2.
local
low complexity
gnu redhat fedoraproject CWE-459
3.3
2024-02-06 CVE-2023-36498 OS Command Injection vulnerability in Tp-Link Er7206 Firmware 1.3.0
A post-authentication command injection vulnerability exists in the PPTP client functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591.
network
low complexity
tp-link CWE-78
7.2
2024-02-06 CVE-2023-42664 OS Command Injection vulnerability in Tp-Link Er7206 Firmware 1.3.0
A post authentication command injection vulnerability exists when setting up the PPTP global configuration of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591.
network
low complexity
tp-link CWE-78
7.2
2024-02-06 CVE-2023-43482 OS Command Injection vulnerability in Tp-Link Er7206 Firmware 1.3.0
A command execution vulnerability exists in the guest resource functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591.
network
low complexity
tp-link CWE-78
7.2
2024-02-06 CVE-2023-46683 OS Command Injection vulnerability in Tp-Link Er7206 Firmware 1.3.0
A post authentication command injection vulnerability exists when configuring the wireguard VPN functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591.
network
low complexity
tp-link CWE-78
7.2
2024-02-06 CVE-2023-47167 OS Command Injection vulnerability in Tp-Link Er7206 Firmware 1.3.0
A post authentication command injection vulnerability exists in the GRE policy functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591.
network
low complexity
tp-link CWE-78
7.2
2024-02-06 CVE-2023-47209 OS Command Injection vulnerability in Tp-Link Er7206 Firmware 1.3.0
A post authentication command injection vulnerability exists in the ipsec policy functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591.
network
low complexity
tp-link CWE-78
7.2
2024-02-06 CVE-2023-47617 OS Command Injection vulnerability in Tp-Link Er7206 Firmware 1.3.0
A post authentication command injection vulnerability exists when configuring the web group member of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591.
network
low complexity
tp-link CWE-78
7.2